📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

The new post-quantum cryptography executive order. Plus: What is Q-Day, really?

IBM Technology44:12

Transcription

There's a really big tsunami of stuff coming at us as cyber security people. If it's not frontier AI models that we've had an awful lot about, it's also obviously AI in itself and how you actually can implement that, implement that in a secure and a safe way.

Q day. That's what they call the day when quantum computing capabilities will finally be able to crack the public key cryptography we rely on to secure everything from websites and email communications to digital signatures, bank accounts, and blockchains. And it might be coming faster than we think.

Last week, US President Donald Trump issued a pair of quantum related executive orders. One of those, securing the nation against advanced cryptographic attacks, establishes a governmentwide mandate to accelerate the United States transition to postquantum cryptography.

Welcome to Security Intelligence, IBM's weekly cyber security podcast. I'm your host, Matt Kazinski, and we have a very special episode for you today all about quantum safety. Later in the show, we'll have Suja Visen, VP Security Products, and Mark Hughes, global managing partner, cyber security services, join us to talk about why we should consider Qday more of a process than an event and what that means for quantum strategies.

But first, we have here Mason Mlesi, who leads IBM's cyber policy strategy, which includes postquantum cryptography. Here with me today, Mason Mleski, who leads IBM's cyber policy strategy, which includes postquantum cryptography. Mason, thank you for joining me. Uh, let's start with an overview. What exactly is this executive order? What's it all about?

So on Monday, President Trump signed an executive order on postpon cryptography, which is just the latest development in a decadelong US government policy effort to address this transition from modern day encryption to new encryption that is uh not susceptible to attacks from quantum computers. uh the this particular executive order represents the US government's transition from recognizing quantum risk to really mandating uh coordinated actions and efforts um you know through establishing clear accountability, clear timelines um and enforcement to ensure our information and data is protected.

To really dive in there, you know what what does that mean? uh you know it establishes first you know that the office of management and budget which is where the the federal CIO uh sits as well as the national cyber director in the white house are going to lead this the strategy representing the level of importance um and coordination that's going to occur across the US government um as well as technical guidance to be coming from our national institute of standards and technology uh our national security agency and our uh cyber security in infrastructure security agency.

Second point is it creates clear accountability. It asks for uh agencies to appoint a lead for postquantum uh cryptography migration efforts uh so that the white house specifically knows who to uh uh who to go to, who to ask questions and who to hold accountable uh for these efforts across the federal government.

>> So can you expand on that for us? What is the EO asking organizations to do?

I think probably one of the most significant things that this executive order does is it accelerates the timeline of the transition that the US government's going to be undertaking. Yeah, there's a lot of a lot of numbers out there in terms of what year people say we need to be uh quantum safe by where quantum computers are actually going to pose a risk to uh regularly breaking encryption. Um and 2035 was kind of an agreed upon date generally uh with the US government before this new executive order accelerates that up to end of 2030 and end of the 2031.

Um and then I think you know and lastly it it helps kind of set the directive of how this matters to to others. You know the US government's going to be updating its acquisition regulation um so that government uh federal contractors are required to comply as well. um and accelerates some of the the processes uh that enable this activity. So the uh the crypto validation to be able to sell products uh they're looking to streamline and enable this in the marketplace.

>> Thanks for breaking that down for us. So I know that the executive order deals, you know, primarily with the functions of the US federal government, but obviously it's got broader implications too, right? So the question is who should be paying attention to this executive order and why?

like you said, I you know, first and foremost, it's the the federal uh government and and the agencies, but I think that it obviously extends well beyond this. As I mentioned, you know, uh federal contractors are going to care about this because the acquisition regulations and what they're going to have to comply with.

Um but at the same time the executive order has like a has a clear focus on on the two other main stakeholders which is in international partners meaning they want to ensure that internationally we adopt all similar standards uh you know ideally leveraging the NIST standards that we've uh spent over a decade developing in the United States with global colleagues uh and that's really to ensure that we have interoperability that when when we talk to someone else overseas uh that that information uh uh can be understood appropriately.

Um and second, it's really the critical infrastructure operators and owners. Um that's water, power, electric, financial. Um many many of these uh sectors are already thinking and working through this. the IT sector, telecommunications, um financial sector are always kind of ahead in this because they they play in this space.

Um but helping uh ensure that our water plants or our hospital systems have the ability to protect information that may never change, that is sensitive, that we want protected, uh is is done so properly. And so the executive order calls for that in in in both ways. calls for department of state and others to work internationally with our partners and allies.

Um and it calls on the you know cyber security uh and infrastructure security agency as well as the sector risk management agencies like health and human services to work with their respective sectors to help enable and support this this major transition for critical infrastructure.

>> Now I always like to close out segments on the show with the so what right the immediate kind of concrete takeaways for our listeners. So Mason, what's the so what here? You know, what do we start doing? Where do we go?

>> First, let's start with why this matters at all. What we're what we're already seeing is bad actors look to gather encrypted data. It's often called, you know, collect now, decrypt later.

Um, collect now, harvest now, decrypt later. Uh that's a very clear indication that you know these adversarial actors understand that they can collect sensitive information that'll have a lifespan whenever a quantum computer is regularly available.

Um and then they can decrypt it then and that's that's not just government secrets. It is government secrets but it you know that extends to like I said healthcare information that will never change about you about you.

Um, it extends to financial information.

Um, and so we are seeing that actively as a risk. It's not all information. Uh we don't think everything needs to move. A takeout menu is is going to change and that the life of that is not uh not something that needs to be protected.

Um, but we do want to ensure that we we're taking this risk based approach to protect the information we need uh for for a long time.

Um, and then you know part of why this matters as well is we've we've this is not the first encryption transition we've been through. Encryption goes back to the Roman days. You know, the Caesar cipher, very simple encryption. It was physically where we would take information, they would encrypt it. That way, it's it's meaningless information in transit physically on horseback or in person, uh, and they would decrypt it with that trusted party at the end. Works the same way. It's just with our laptops now.

Um, but that transitions then as well as transitions now over the last you know 50 years with computers um have taken years and years and years. We still haven't fully completed past encryption transitions.

Um, so even if we think a quantum computer won't be available until 2040 um it could easily take that long um until something is available. And the the timelines of when quantum computers that may risk this could become available are as soon as this decade possibly which means we could potentially already be um behind or starting to you know put information at risk.

>> So given these risks uh what do you recommend organizations start doing today?

The good news is we you know the US government has been doing this work. uh the the world has undertaken you know very collaborative effort to create these new post-quantum encryption standards um and those standards have are are out um and now you know what's happening industry has taken those um IBM has helped create those standards um so it may have a a jump start but now we are commercializing those into products into solutions um that first secure the the products that we sell um because most most organizations are just going to buy. They're not going to be doing this work themselves. So they they want to ensure that they are buying um products that are quantum safe.

And second, we're we're developing products um and services that help organizations understand what they have, what risk they have um and how they can make this this this successful transition.

Finally, just to put a a fine point on this, you know, we we we have a very clear kind of perspective that we talk with with governments.

Um, and the US government is not the only one doing this. You know, a dozen or so governments worldwide updated postpon cryptography policies last year. Another dozen or so created new ones.

Um, we're seeing sector guidance already start to come out.

Um, so the collectively the world is is kind of moving towards um ensuring the security.

Um, but but our our you know as governments think about this our our guidance to them is clear. It's it comes in three phases. It's it's make sure that we plan make sure that we act make sure that we motivate.

Planning means we have to as governments, as nations work to get road mapaps, get readiness together, integrate uh PQC into existing national cyber security strategies, doing the big weighty process heavy things, getting the budget aligned to ensure that we can do this successfully.

Uh it means ensuring we prioritize like I said before. Not all information's the same uh value, the same sensitivity over the same uh lifetime. So understanding what you have, how sensitive it is, how valuable it is over time is what matters and prioritizing where you need to do this.

This is kind of where the the executive order really steps up. It says we are not just going to to plan and to talk about doing this. We actually want tangible action. It calls for pilots specific like pilots 2027 that's next year quick quick action to have lessons learned to actually migrate you know it set the EO sets forward clear migration deadlines 2030 2031 um and from those things it's it's clear to say like we need to rep replicate and grow those examples.

So that that's part of what the support to critical infrastructure will be is a power plant pretty pretty um important. The data may be less sensitive. So it may happen slightly later but the it'll it'll have lessons learned from across the government sector.

And finally it's it's really about motivating um not just US uh US government federal agencies to act. It's about ensuring that all organizations, critical infrastructure, other private organizations worldwide, um are educated enough to know what they should be thinking about, what they need to know, what they don't need to know, um and what to do, how to take action, what tools and resources are out there and available.

>> Thank you, Mason, for hopping on with us today. Switching gears now, here is a pre-recorded conversation with Suji Vuen and Mark Hughes, hence the change in wardrobe and location that our video viewers will pick up on. I want to dive right in up top and just ask if you you can outline for our listeners what exactly are the concerns when it comes to quantum computing and security. What is the risk of Qday? Mark, you want to start us off?

the the main issue as you teed up up up front is that the quantum computing capability that we're going to have is going to essentially be able to run an algorithm which we've known about for some years called Shaw's algorithm which essentially unravels for a better description the uh PKI uh encryption algorithm and what that means is that therefore a lot of the stuff that we rely on today in terms of encryption is going to become vulnerable and therefore we have to do something about it so the the so-called Q day which is a bit mleading because it's not a day. It's actually going to be a process. But the point is that the quantum computing capability that's now emerging is going to essentially undermine uh the encryption, a lot of the encryption, asymmetric encryption that we rely upon today.

>> Absolutely. And I'm glad you gesture towards the fact that Qday is kind of maybe more of a process than just the day because I do want to dig into that with you folks both. You wrote a great article about this. Uh but before we do, um Suja, I just wanted to, you know, ask for your kind of topline overview. Anything to add to to to what Mark set up there for us about the the risks of quantum uh uh to cyber security?

I mean just like everything else right today the AI wave because of that the identities are exploding and then we need to be ahead of it and when you are taking care of it you might as well take care of the postquantum thing as well as Mark pointed out it's not a point in time like Y2K after that after QA everything gets better it's it comes in waves not in shocks so it we have to be prepared for it that is why we are talking about it today even though You can say it's five years and it's anybody's guess at this point as you point Google is having a date, IBM has a date, government has a date. So that's all fine but it's a journey. So are we getting prepared for that?

>> And uh you know I I it does come at a time like you said we're also dealing with this AI and how it's changing security and it just it feels like a lot. You know there are cyber security professionals have a lot to be thinking about.

Um, Mark, does it complicate things that we've got AI and quantum both like together? Like like how does that play out for us?

>> No, of course not, Matt. It makes a lot more interesting.

>> No. Yeah. I mean, look, I think Sujo Sujo will agree with me. There's a really big tsunami of stuff coming at us as cyber security people um uh at the moment. Um, if it's not frontier AI models that we've heard an awful lot about, it's also obviously AI in itself and how you actually can implement that, implement that in a secure and a safe way in most organizations. SUJ talked about the identities that come with that. A lot of organizations are really struggling with how to get the best out of AI because they can't work out yet how to implement it securely with the right levels of access. And then of course you got con alongside there as well. So there's a lot. But Matt, the good news is that within all of that, there's a few foundational principles that we work at with cyber security and a lot of those foundational things don't change.

Um, but the one thing that does change is we've got to speed up because a lot of the quantum uh impending quantum revolution and also what we're seeing with AI means that we got to do a lot of the things that we know how to do, we got to do them a lot quicker.

I'm glad you also you referenced the foundational stuff because I do want to come back to that. But, you know, we we've kind of set up the the scene here for folks, but I really want to dive into what I think is kind of the crux of the conversation today. And it is this idea that Qday is not really a when, it's a process. Right. Back in April, you folks published a co-authored article that kind of gave your take on this matter. Here's a quote from that. Unlike Y2K, there won't be a single moment when everything breaks at once. Rather quantum risk will be realized over time spanning multiple years as different cryptographic systems become vulnerable at different times. That was really fascinating to me because I've been hearing for years about Qday as like a specific moment, right? And this is like no, it's an unfolding process in time. We're dealing with it already. Suja, could you elaborate a bit for us on what it means to view Qday as something that happens over time rather than a sudden event.

>> Since we wrote, our thinking hasn't changed. I believe Mark and I agree. uh as I said this comes in waves because when we think about cryptography right which is encryption uh this is invisible scaffolding if you will for the modern uh software so when Qday the quantity doesn't break just encryption it breaks a lot of our assumptions that we have had for years on this one and because of that it's the hardware it is your credentials it's your P the PKI eyes that Mark was talking about. So everything needs to change and so this is not just a technology problem, it's the people, the process. So the biggest bottleneck is execution.

Um Matt, we know about the data in general stays for 10 years. Financial institutions, they say they keep the data for 10 years. something that is today 2026. Today's data needs to at least last until 2036. If you think about healthcare data, it needs to be held on for the lifetime of a person. So these are all important data which are encrypted and kept. How do we make sure that they are safe? How do we prevent them from harvest now and decrypt later? Because the bad actors are already taking this data today to decrypt later. How do we stop that? That is why it's a journeys because you need to be starting on the journey because first we don't even know. We cannot fix things that we don't know because cryptography is something that we will put on and don't worry about for a year or two years and then they will take a look at it. Today we need to be looking at it and make sure that our hardware software our third party vendor software that you are having all of them are ready for this new world

>> and and and it's a good thing that it's a process because you have time to work through it almost right like yes there are issues that we're starting to deal with already but we can start thinking about them as we move along. Mark anything to add there in terms of you know how our thinking changes when we see Qday as a process?

Yeah massively important what you were saying it really is pervasive and it's not an area in cryptography that was absolutely essential because the one thing about cryptography more broadly when when things don't work when certificates don't work whatever everything stops things can't handshake properly and so it's a it's a really important area but one which we have got pretty well working well and we have had over many many years. The the the thing now though is as we enter this this period we really now have to start rethinking the way we approach this in a way in which we necessarily haven't done to do for some time. So of course that that demands as S was saying a different approach which pervades right across many different parts of the whole IT ecosystem. So it it there's a lot of little pieces of the of the if you essentially that ecosystem that I was talking about that need to be addressed that really uh uh starts with understanding what's out there and as you said you can't you can't deal with something that you don't know about and so just getting to that discovery point is a pretty important step in all of this which actually is not to do with anything complex around algorithms or anything that we can get to that later it's actually just starting about well what have you got already and what do you know about today and once you can get to that point then you can begin to work out well how you going to prioritize and how you going to manage it over that that time period

>> yeah I like that framing a lot because I think especially We talk about quantum, it can feel like a radical break from what's out there, right? Like it can feel like something that's totally different than what we're used to. But you a couple times now, Mark, have gestures towards like look, it starts with understanding what you already have, what's in place and and applying some fundamental principles just to a new kind of realm. And in this way, I see again that parallel between quantum and AI where like it can feel so different from what we've seen before, but a lot of what we know can still be transferred over to this area. It's just about okay the terrain has changed so how do we implement things the right way.

Um, and I want to ask too because like I said this this idea of Qday as a process was new to me and it was very clarifying. I would love to get your take on how the rest of the industry talks about this. Do you think the kind of tenor of our Qday conversations is it on the right track? Are we sensational? Are we not sensational enough? And Suja I'll ask you first. Do you feel like we've got the right conversation out there or do you worry that we need to change the framing? How do you feel about it?

>> Look, from when I when I think about last year to this year, I do see people are taking it much more seriously. Today, we have we see about 30% of the industry have started on this journey. Okay, I'm not saying they are in the they at least started on a they started at least in the strategize and discovery phase, right? So they are at least beginning in that which shows especially because of regulations and also the finance and the healthcare industry and telecom industry are the in the forefront of it because it's matters for the critical infrastructure to be ready for this quantum era. So I do see that the conversation has started but we are only at 30% and we are in the first two stages.

I'd love to shift gears now to talking about the the so what. Right. The point of this show is to to offer people kind of pragmatic concrete takeaways. Right. So let's start with talking about what does it mean for us that we are at the beginning of the kind of Q-day process thinking about this stuff. Where do we get started? And and Mark, I want to ask you especially because earlier you had mentioned, you know, some of the foundational stuff of cyber security still applies here. And I was wondering if you could start maybe let's talk about that first. What's the foundational stuff that still applies to a kind of postquantum world? Can you walk us through that?

>> Yeah, first things first is actually just realizing that there is an impending issue coming up and as Suji was saying 30% of organizations really needs to be a lot more than that because as you said right at the beginning regardless of when the day is if it's 29 or whatever when we know that the capability will exist won't necessarily be immediately accessible for everyone to get to but the capability will exist to undermine current asymmetric encryption. uh that that that is not far away. And when you think about the complexity of the interwoven nature of hardware software and how interoperability happens between different organizations, unpicking that to discover where those cryptographic artifacts are and then doing something about it is pretty urgent. And so what the so the starting thing is actually organizations have got to realize this needs to be addressed. And this is not a you know we just do it once and that's it. And we can talk a bit more about that later on, but the reality is this is a process um that starts with really getting and digging deep into something that perhaps organizations haven't had to do for some time. So it's an awareness point to start with and that really has to be driven from really a pretty high level within an organization because there's so many different piece pieces of the ecosystem need to be touched and also the flow down interoperability that has to happen in their supply chains. If you think about the average enterprise, you know, there's a lot to think about. So the first thing is literally just getting the awareness to say, "Hey, we've got to get off to this and start addressing it." And then really is the next biggest step in this journey is, as you've probably realized already, Matt, as Sra and I have alluded to, is how do you discover what you've got? Because you can't deal with stuff that you don't know if you don't know it's there. So that discovery exercise, where are these cryptographic artifacts? Who am I working with? what are they doing in terms of because if they start doing some changes and then the organization that you're in hasn't done those changes then obviously that could cause you some trouble in terms of interoperability and now's the time to think through that when we've got time I'm afraid to do that and leave that much longer if you're in a pressured situation where others are changing around you and you haven't got on with it soon enough and got on at least with a decent amount of discovery at this stage you could find yourself in a lot of trouble so really now is the time to get going and to going with that uh that discovery exercise.

>> Absolutely. And and you brought up something there that I didn't really think about at all and it feels like a major, you know, uh uh uh miss for me, which is that like this is also a supply chain issue, right? Like like you said, even if maybe you're addressing some of the cryptography uh in your own systems nowadays, nobody's making like software in in a vacuum. We're using, you know, open- source libraries or code that other people have written. We're pulling it all together. So you could have your whole you know uh uh thieftdom can be all set up but if somebody's got got something you know if they haven't touched it in theirs that can be a huge issue. Suja any thoughts there on like you know discovery like Mark said is huge especially in this supply chain that we have built is very complex of our supply chain. Any thoughts on on how we actually discover these things? What do we do?

>> That's why this is not a project project it's a transformation. Right. The first one is you strategize right? Okay my because this is hardware software network all of these and like you said it's a supply chain all your your vendors when are they going to be ready so this is if if your vendor is not planning to be ready then you have to have alternate that means it's a migration uh project so that is why the strategizing is very very important then as I saying like we mark talked about the discovery part of it then you figure out how you're going to modernize it when you modernize this is a transformation product you have to govern and make sure that it doesn't waiver from where it is and then you remediate when the QA comes when the algorithms are available you are ready to be agile and remediate and the cycle continues right this is not it's a five-step but this fivestep keeps going it's in a circle right you strategize as modernize governiate and then it keeps going and the biggest thing for us the strategizing is we t you you talked about supply chain if you're doing a hardware refresh today right you don't do it every Yeah, you want to make sure that they are quantum ready so that you don't have to be spending money unnecessarily. That is why we are starting today. Same thing the certificate life cycle is changing. It used to be a year then it became 200 now it's becoming 100 then and it is reducing it. Think about how are you going to make sure that they are quantum ready that way because you can use some of these to accelerate your path and be ready for the new world because look this is not a question of whether a company is going to do it or not. This is about like who's going to start first because that is what that person is going to have the advantage because if when you do it last minute it's going to be very very expensive. Very very expensive. Yeah, it's going to be very very expensive.

And it also I could see, you know, you talk about like you have to work with your vendors, right? And if you have a vendor who hasn't isn't thinking about this or you are a vendor who's not thinking about this, you could lose some trust from from customers, right? Like if you're not starting to think about this and they come to you and they say, "Hey, what are you doing for postquantum cryptography?" And they're like, "Nothing that people are going to start looking elsewhere, you know."

Um, and you mentioned SUJA, you know, modernization, right? Once you've actually looked at everything and and you've kind of inventoried, you figured out who you're working with, you're getting started, you want to do some modernization. And that makes me think about, you know, postquantum cryptography or quantum safe cryptography, which is I think when we talk about Qday, that's the kind of the topline thing that comes up a lot, which is like you got to get that postquantum cryptography.

>> What exactly is that though, Mark? Could you give us a kind of overview of what's the difference between cryptography and PQC, postquantum cryptography? What makes those things different?

It's a great question. So, look, uh, at the National Institute of Science and Technology ran a ran a competition a few years ago to to really uh to to for organizations to actually develop new cryptography um that that can't be unraveled by quantum computing to the best of our knowledge. And that's important because this will come back to our notion of what we call crypto agility because in the future we seeing we see cryptography being not so static as as content computing capabilities continue to to emerge and become more powerful. Then we see that the cryptographic approach is going to have to change as that happens. But for today uh in as we see uh quantum uh quantum computing capability being available uh the approach is that there have been a number of algorithms that have been developed. There are four and IBM IBM has been at the absolute forefront of developing those uh those postquantum resistant algorithms. And so what we mean by postquantum cryptography is those algorithms exist. Now here's the catch. And the catch is that of course the quantum compute capability means that the algorithms have to be more sophisticated um because they have to be able to withstand the now this new compute capability that's going to emerge because obviously that's very different from what we have today. So they are more complicated they are potentially bigger and they have different characteristics. So it this is not a one forone swap. So at the moment we have four postquantum resistant algorithms. In the future there could be more. and the way in which we deploy those and we think about how we deploy them and most importantly during this transition period where organizations are in this transformation they're going to have to make some choices about which is the most appropriate and uh and necessary algorithm to deploy uh in different scenarios. So that's really why there this there is a shift from what was a fairly static environment to now this environment where there are some choices based upon the complexity of the cryptographic algorithms that are postquantum resistant and that will continue to emerge and develop uh we think in the future as well.

Yeah, it's like such just said, right? This is a cycle that doesn't stop. You might reach a kind of a moment of crypto safety or postquantum safety and then that might change again and you might need another algorithm or another way of implementing it.

>> PTQ is necessary but it's not sufficient. Crypto agility is the endgame, right? Are you agile enough? Because we are used to having an encryption and forgetting about it, right? Because we are safe. Now you need to be agile and we'll be able to change as these algorithms mature. As things mature, are you able to be agile to take in? That means your protocols need to be upgraded. Your systems need is it's a hardware, software, everything needs to be thought about and upgraded. So you can be agile.

>> This is as Sid was saying, this is a real transformation and a transformation not just in terms of we've got to do this big project. No, this is a transformation to how you operate. And in many respects when we think about how AI is impacting our IT stack, you know, that that is also a transformation in how we're operating as well. And that's where I think many organizations that su and I talk to and you have got to start with thinking about it in that way real transformation ground up how do we think differently now and to get to a state of crypto agility and that's different as such was saying from today so it's this notion of we've got to think much more dynamically be much more prepared to think we have to reopen revisit as new things emerge and that I think is going to be a theme not just in the postquantum cryptography space but if you think about it just in terms of what quantum and computing is going to offer for us in the first place. Right? Today we've got some ideas what that will be able to do, but in the future I think that will impact on the whole IT stack as well. So there's this notion that we are now much more in this way of being able to think about it much less static, much more dynamic um and changing rapidly.

Yeah, it reminds me, you know, again, I didn't see these parallels before I started talking to you folks for this this, you know, episode, but it's almost like we're developing a similar kind of, and you can tell me if I'm wrong here, but it's almost like we're developing a a similar kind of agility with AI in terms of like how the new models keep coming out and you kind of have like you can't just sit and wait for, you know, like, okay, this, you know, Mythos preview is the model to end all models. Oops, no, it's not. Right? Like, and I feel like that's what we're saying about kind of quantum computing and quantum cryptography, right? is that like it's not going to be a thing where we find the one thing that we sit on for the next 20 30 years, right? It's going to be developing that agility. And we've said this term a few times now, crypto agility, and it might be useful to just kind of define it explicitly for our listeners.

Um, Suja, do you have like a definition of crypto agility? What does that mean to you?

>> Crypto agility is the ability to change your cryptography as easily as a software upgrade, right? You're updating your software. Today, that is not how it happens. It takes it's it's it's a huge transformation journey. We want to be in a place that you just hey I'm able to update it like I update a software. So because the cryptography as Mark was pointing out will be changing and evolving and vulnerabilities will emerge and then the threats will shift. So that's what it is. So for me it's about can you upgrade it just like you do a software upgrade. You just put it in the night in your phone or something upgrade and it upgraded instead of having to go do this massive transformation.

>> So the transformation Matt as S is saying, the transformation is about getting to a state where you can do that not just about where you've worked out which are the best new bits of cryptographic artifacts to replace the ones that you've got today. So it's a it's you got to think about it in that way. And what I what I would also add is when talking to to many clients as Sudra and I do is when you think about that whole environment that whole changing nature that does make people certainly lots of clients that I talk to feel pretty uncomfortable actually because it's like so this is not a one and done. This is not I can do this and then I'm done. No, no, no. is going to be an ongoing as we said crypto agile approach as is as are now many other things in the IT environment and that that it's you know there's this notion that it's okay a few things will happen it will be a bit disruptive and then everything will settle down and then we can just go back to how we used to be now that's not how it's going to be now um and some people are really excited about that uh you can probably tell that SAR and I are very excited about that but um some others are you find that a bit a bit bit hard to deal with and understandably so because it's like constant change um and that presents challenges but it presents a lot of opportunity as well

>> and it's it's overwhelming so I know I I made it simple saying that hey it should be as easy so what can you do so first thing is when you're architecting make sure that you're designing into the architecture right and the second one is knowing I think Mark you had mentioned knowing where your cryptography lives your certificates algorithms keys where where do they live that's where discovering and knowing that becomes visibility becomes very important and then decoupling this cryptography from your application so that it's not been built in your application and you're this is you talked about the model example this is something that you reach out and then get it when you need it then automating the life cycle right if a certificate is expiring you're not finding out later and then systems are down you are automating this and building into the system and establishing clean governance so that when changes are systematic and you're not doing reactively so when you do that in a in in that fashion it becomes much easier That is why it's a transformation journey that each one of our enterprises including us IBM has scanned thousands of repos millions of lines of code building the cryptographic bill of material. So we understand we are in the same journey just like we are a vendor we are also in our own journey and we are learning from it and then we are able to share it with our clients.

Yeah, I you know what's really cool to me here is that I walked into this conversation thinking the transformation was just from cryptography to postquantum cryptography. But it is so much more than that and and I can see now, you know, why you would say this is exciting because there is something really cool about this idea of like what if your cryptography was as agile as a software update, right? What if you didn't have to commit to an algorithm for decades? You could use it when it was the strongest and when you needed to change it out, you could change it out. That's exciting.

Um, I I feel kind of energized by that almost. Um, I I do. So we're we're we're starting to run low on time here and there's two more things I just want to ask you folks about real quick. The first is we spent a lot of time here talking about kind of quantum computing as a big cyber security risk. But I also am kind of wondering if quantum computing might have some benefits for us too. like you know I and I again not to hit the parallels too hard but I think about AI right we talk about it as a cyber security risk a lot but we also talk about it as a major cyber security boon uh Mark any thoughts on like will quantum also be good for us in some ways what do you think

>> yeah I mean look trust security to come along and spoil the party as as is often the case but I try not to and Sudra and I really try not to it's um it's it's it's it's only one slither of what quantum is going to bring us and everyone wants wants to talk about it and they should talk about it because as we said it's urgent that we need to address it but it is only one thing which is that in the space that where quantum is going to bring us this unbelievable ability to to to perform very complex algorithm algorithmic algorithmic tasks right that's one of the big use cases that quantum is going to bring us that one bit in there which is the ability to run the algorithm that's going to defeat uh some of our existing asymmetric encryption that's the only thing really which we have here which is the security focus Because downside of it, there are so many upsides. If you just go beyond the well start with that algorithmic capability which is going to exist now, there are so many things uh that you know clients are already working with us on. Think about complex uh financial ways of trading and transactions. You know there's there's there's complex algorithmic solutioning that quantum is going to bring us that we can't do at the moment. Even if the compute capabilities are as good as they are, Quantum is going to really change that. We think about the whole area around natural sciences and the natural world. How we can emulate the natural world and especially in the life sciences and medical applications of thinking about how we can really use quantum computing to unfold proteins and give us the ability to actually target for example treatment schedules and medicines designed specifically for individuals really based upon the understanding that a quantum is going to bring us to be able to actually unlock some of the uh those processes that we haven't been able to in the natural world. So there are many even just at this beginning point of quantum computing we can already see some clear use cases that are going to bring us some fabulous capabilities and of course in security as well those some of those things apply in terms of being able to now process complex algorithms manage data do sensing uh in a way in which we can't get anywhere near at the moment. You know that quantum capability is going to give us that as well and give us the ability to respond and react much more quickly. So lots and lots of different applications Matt which are really exciting and which are already people are beginning to talk about. The one thing I would say actually is that because everyone's so fixated on AI and AI deployment that they're sort of forgetting that this huge revolution with all the benefits that will come from it is uh is coming to us and we really need to start thinking about it because there's endless capability and opportunity I think with it.

For me the healthcare right the amount of the compute the research that we can do and then solve a lot of like these niche one in a million somebody is suffering and because of that we don't have enough compute to do research and figure it out can be unlocked with the quantum computers look we put the quantum computers on the cloud 10 years back we have quarter million people already using it and published 6,000 plus research papers and it's really really exciting to see this is this is another era just like what we saw with AI and everything else that's emerging and this is going to be really really good. Yes, with everything we are to be ready for that that we have the time to get ready for the QA uh so we can get there but what we will see on the other side it's really really exciting and personally for me it is on the medical field because and we see lot of partners who are putting uh putting our quantum computers in their labs to go and start experimenting on one is in the research side of the world education and also in healthcare so I'm really excited about that

>> absolutely and yeah you know I I just to to step back for a second. Something you had mentioned there, Mark. I do I kind of agree with you that like AI gets a lot of the headlines right now, but like quantum has been making these quiet leaps in the background and really reaching levels that like just a few years ago I'm not sure that we could have even imagined and so like I think some really exciting things are on the horizon and I agree with you Suja, you know, looking at those real world applications of like think about medicine what could change there.

Um, but to close us out today, folks, I always like to end the show on kind of the a practical note, right? So, let's imagine somebody's sitting there listening to this episode. They're saying, "This all sounds amazing. What do I actually do right now?" Like, what do how do I get started? What's the first kind of steps I take? Mark, I'll ask you first your thoughts on like if you're an organization today, where do you get started on this?

get a conversation going immediately at the highest level in the organization to say that this is coming and we need to address in a transformational way how we think about cryptography and then start deploying tools to start discovering uh where you have crypto cryptographic artifacts across the organization to then get to that cryptographic bill of materials and then you'll have a chance of being able to then think about what the strategy needs to be and the mitigation options to you uh as algorithms that are available now can be deployed or other mitigating uh strategies. So have a conversation, get going with discovery straight away.

>> Strategize and discovery. That is the biggest thing that you can start with. Uh a few things. The non-human identities which used to be like 20 to one with human identity is now 50 and I and when I when I was looking up before this meeting it was 109 or something like that. So it is exponentially increasing. That's number one. So when these things are already increasing it's important to get started. For me, the enterprises that that are going to win are not the one that's move fast. That's the one that start early.

>> Folks, that does it for today's episode. Thank you so much to Mason and Sua and Mark. Thank you to the viewers and the listeners. Thank you to our producers. Subscribe to Security Intelligence wherever podcasts are found so that you never miss an episode. Stay safe out there. And if you have questions, comments, or concerns about Qday and the quantum future, drop them in the YouTube comments. We love to hear from you. And don't forget to check out our latest bonus episode with Ryan Anuts. We talk all about patch management and why we need to actually ditch it for a new approach he calls exposure management. That's available on all the usual audio platforms right now.